arXiv AI By Linfeng Jiang, Steven McDonagh, Yuhang Chen, Xingyu Zhao, Siddartha Khastgir, Andi Zhang

Let the Carrier Carry the Attack: Preserving the Subject in Adversarial Image Generation

Read the original on arXiv AI →

The paper introduces a "carrier"—a secondary visual element—to help preserve the main subject of an image during strong, unrestricted adversarial attacks. By allocating a larger portion of globally normalized attack updates to the carrier, the method reduces distortion of the subject while maintaining attack strength. Additionally, the carrier enhances cross-model transferability and allows targeted attacks to mislead classifiers while keeping the subject recognizable to humans.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv Computer Vision
Sep 7

FSPGD: Rethinking Black-box Attacks on Semantic Segmentation

FSPGD introduces a feature-space black-box attack for semantic segmentation that targets intermediate representations rather than just output logits. The method uses a dual loss: an external loss to disrupt cross-model feature alignment and an internal loss to reduce consistency among same-class instances. Experiments on Pascal VOC 2012 and Cityscapes show that FSPGD outperforms existing logit-level and segmentation-specific attacks across CNN and Transformer backbones, and its adversarial examples improve robustness when used for training.

By Eun-Sol Park, MiSo Park, Yong-Goo Shin